Ò׽ؽØͼÈí¼þ¡¢µ¥Îļþ¡¢Ãâ°²×°¡¢´¿ÂÌÉ«¡¢½ö160KB

hacking oracle±Ê¼Ç

###author:hiphop###
###qq:70381908###
ΪʲôҪ¹Ø×¢ Oracle ?
ÒòΪOracle ±»´óÁ¿ÆóÒµËùʹÓÃ,ÓÐÐí¶àÄ¿±ê¿ÉÒÔÑ¡ÔñÀ´Éø͸
Ðí¶àÆóÒµ¶¼Ã»ÓиüÐÂÇÒÓÐDZÔڵķ½ÏÕ!
ÌáȨ·Ç³£¼òµ¥,ÈÝÒ×Äõ½shell!!
¶ÁÁËblackhat paper ÈÃÎÒ¿ªÊ¼À´Ñо¿Oracle
ÒòΪËûÖ»½²µ½Ò»Ð¡²¿·Ý ÕæÕý°²È«ÎÊÌ⻹ÓкܹãµÄ
Ö»ÊǹúÄÚºÃÏñºÜÉÙÍÚ¾ò
ÒòΪÓöµ½µÄ»·¾³²»¶à
µ«ÊÇ°¢ Oracle ÊÇ free download ºÇºÇ
¸¶·Ñ²Å¿ÉÒÔupgrade
Ò»°ãÁ¬½Ó Oracle ÐèÒªÒÔϼ¸¸öÌõ¼þ£º
IP
PORT
SID
username/password
The Oracle listener default port is 1521
generally in the 1521-1540 range
ɨÃè´Ì̽²»»á¸úÄã˵ÓÃʲô°æ±¾µ«Ð°æµÄnmap ¿ÉÒÔÈ¡µÃµ½Ò»Ð©,ʹÓÃTNS packet¿ÉÒÔ½â¾öÕâ¸öÎÊÌâ
TNS packet ¿ÉÒÔÁ˽â oracle °æ±¾
SID ´Ì̽·½Ê½:
1.TNS listener directly
2.brute force for default sid
3.query other component ¿ÉÄÜ°üº¬ÓÐSID
u/p Æƽâ
ÌáȨ·½·¨:
Ìá權 1 java function
Win32Exec
Ìá權2 smbrelay
Run OS commands via sql injection in web applications
Run OS commands via create table
Run OS commands via dbms scheduler
Run OS commands via PL/SQL and Extproc
Run OS commands via Java
Run OS commands via Oracle Text
Run OS commands via PL/SQL Native (9i)
Run OS commands via PL/SQL Native (10g / 11g)
Run OS commands via alter system set events
»¹»á½ÐøÔö¼Ó£¡£¡
´ËÎÄÖ»ÊÇÎÒµÄresearch µÄС±Ê¼Ç
ÁíÍâ½éÉÜÒ»¿î¹¤¾ß ¿ÉÒÔ×öµ½²¿·Ýà¡ pyдµÄ
download£º http://inguma.sourceforge.net/
demo£ºhttp://inguma.sourceforge.net/text/inguma_text.html
×¢:
Oracle default port list
Oracle HTTP Server listen port / Oracle HTTP Server port
80
Oracle Application Server
Edit httpd.conf and restart OHS
Oracle Internet Directory(non-SSL)
389
Oracle Application Server
 
Oracle HTTP Server SSL port
443
Oracle Application Server
Edit httpd.conf and restart OHS
Oracle Internet Directory(SSL)
636
Oracle Application Server
 
Oracle Net Listener / Enterprise Manager Repository port
1521
Oracle Application Server / Oracle Database
Edit listener.ora and restart listener
Oracle Net Listener
1526
Oracle Database
Edit listener.ora and restart listen


Ïà¹ØÎĵµ£º

Æô¶¯oracleϵͳÎļþ¼ÓÔØ˳Ðò

ÔÚÆô¶¯oracle·þÎñʱ,Ê×ÏÈ»áÔÚ·þÎñ¶ËÕÒ
1.spfile<sid>.ora
ÓÃÓÚÆô¶¯Àý³Ì,Èç¹ûÕÒ²»µ½spfile<sid>.ora,ÔòʹÓ÷þÎñ¶ËȱʡµÄ
2.spfile
À´Æô¶¯,Èç¹ûȱʡµÄspfileÒ²ÕÒ²»µ½,ÔòʹÓÃ
3.init<sid>.ora
À´Æô¶¯Àý³Ì,×îºóÔòÊÇʹÓÃȱʡµÄ
4.pfile
.µ±È»ÄãÒ²¿ÉÒÔÖ¸¶¨pfileÀ´¸²¸ÇȱʡspfileÆô¶¯Àý³Ì,»òͨ¹ýspfile= ......

Oracle¶¨ÒåÔ¼Êø Íâ¼üÔ¼Êø

Íâ¼üÔ¼Êø±£Ö¤²ÎÕÕÍêÕûÐÔ¡£Íâ¼üÔ¼ÊøÏÞ¶¨ÁËÒ»¸öÁеÄÈ¡Öµ·¶Î§¡£Ò»¸öÀý×Ó¾ÍÊÇÏÞ¶¨ÖÝÃûËõдÔÚÒ»¸öÓÐÏÞÖµ¼¯ºÏÖУ¬Õâ¸öÖµ¼¯ºÏÊÇÁíÍâÒ»¸ö¿ØÖƽṹ——Ò»ÕŸ¸±í
    ÏÂÃæÎÒÃÇ´´½¨Ò»ÕŲÎÕÕ±í£¬ËüÌṩÁËÍêÕûµÄÖÝËõдÁÐ±í£¬È»ºóʹÓòÎÕÕÍêÕûÐÔÈ·±£Ñ§ÉúÃÇÓÐÕýÈ·µÄÖÝËõд¡£µÚÒ»ÕűíÊÇÖݲÎÕÕ±í£¬State×÷ΪÖ÷¼ü
......

ORACLE³£Óýű¾ÃüÁî

Óû§µÄ¹ÜÀí
Ò»¡¢ORACLEµÄ°²È«Óò
1¡¢TABLESPACE QUOTAS£º±í¿Õ¼äµÄʹÓö¨¶î
2¡¢DEFAULT TABLESPACE£ºÄ¬Èϱí¿Õ¼ä
3¡¢TEMPORARY TABLESPACE£ºÖ¸¶¨ÁÙʱ±í¿Õ¼ä¡£
4¡¢ACCOUNT LOCKING£ºÓû§Ëø
5¡¢RESOURCE LIMITE£º×ÊÔ´ÏÞÖÆ
6¡¢DIRECT PRIVILEGES£ºÖ±½ÓÊÚȨ
7¡¢ROLE PRIVILEGES£º½ÇÉ«ÊÚȨÏȽ«Ó¦ÓÃÖеÄÓû§»®Îª²»Í¬µÄ½ÇÉ«£¬ ......

oracle ´æ´¢¹ý³ÌµÄ»ù±¾Óï·¨


1.»ù±¾½á¹¹
CREATE OR REPLACE PROCEDURE ´æ´¢¹ý³ÌÃû×Ö
(
    ²ÎÊý1 IN NUMBER,
    ²ÎÊý2 IN NUMBER
) IS
±äÁ¿1 INTEGER :=0;
±äÁ¿2 DATE;
BEGIN
END ´æ´¢¹ý³ÌÃû×Ö
2.SELECT INTO STATEMENT
  ½«select²éѯµÄ½á¹û´æÈëµ½±äÁ¿ÖУ¬¿ÉÒÔͬʱ½«¶à¸öÁд洢¶à¸ö±äÁ¿Ö ......

ÔÚAIX»·¾³ÏÂΪOracle¡¢sybase ʹÓÃÂãÉ豸 ¼¯ÖÐÌÖÂÛ35

¡¶oracle´óÐÍÊý¾Ý¿âϵͳÔÚAIX/unixÉϵÄʵսÏê½â¡·¼¯ÖÐÌÖÂÛ35£ºÔÚAIX»·¾³ÏÂΪOracle¡¢sybase ʹÓÃÂãÉ豸   ÎÄƽ    ÂãÉ豸ÊÂÒ»ÖÖÔÚUNIXϳ£ÓõÄÊý¾Ý¿âÊý¾Ý´æ´¢·½Ê½,ÔÚAIXÖÐÈç´Ë,ÔÚHP-UX\SCO UNIXµÈϵͳÖнÔÊÇÈç´Ë¡£Õâ¶ÎʱÆÚÒÔÀ´Ò»Ö±ÓÐͬ־ÃÇÓʼþѯÎÊÈçºÎʹÓÃÂãÉ豸¡£ÕâÀïÎÒ»ã×ÜһЩAIXÏÂÂãÉ豸µÄʹÓÃÎ ......
© 2009 ej38.com All Rights Reserved. ¹ØÓÚE½¡ÍøÁªÏµÎÒÃÇ | Õ¾µãµØͼ | ¸ÓICP±¸09004571ºÅ